DEBIAN-CVE-2018-18511
Advisory lineage Upstream: 1 Downstream: 4
Upstream
Downstream
Published: 26 Apr 2019, 17:29
Last modified:28 Apr 2026, 20:19
Vulnerability Summary
Overall Risk (default)
low
17/100 CVSS Score
4.3 MEDIUM
3.0 (osv_debian)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
26 Apr 2019, 17:29
Published
Vulnerability first disclosed
28 Apr 2026, 20:19
Last Modified
Vulnerability information updated
Description
Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1.
CVSS Metrics
- v3.0•MEDIUM•Score: 4.3CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Affected Systems
- debian•firefox-esr
< 60.7.0esr-1 | < 60.7.0esr-1 | < 60.7.0esr-1 | < 60.7.0esr-1
- debian•thunderbird
< 1:60.7.0-1 | < 1:60.7.0-1 | < 1:60.7.0-1 | < 1:60.7.0-1